Local File Deletion Vulnerability in ASUS System Control Interface
CVE-2022-36439
6MEDIUM
Key Information:
- Vendor
- Asus
- Vendor
- CVE Published:
- 18 October 2022
Summary
AsusSoftwareManager.exe within the ASUS System Control Interface on ASUS personal computers running Windows allows unauthorized local users to manipulate files in the Temp directory. Specifically, this vulnerability permits a local user to not only write to the Temp directory but also delete higher privileged files, which could potentially compromise system integrity. The affected versions of the ASUS System Control Interface, AsusSoftwareManger.exe, and AsusLiveUpdate.dll reflect a significant security risk that needs to be addressed promptly.
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved